Totolink

T6

165 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 14:17:34

Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.36%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:19

Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.3%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 15:17:19

Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 02.09.2026 16:17:17

Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.34%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:23

Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.44%
  • Veröffentlicht 31.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 14:17:34

Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:21

Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 02.09.2026 19:17:19

Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:21

Incorrect access control in the getDeviceInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain device identification details via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • EPSS 0.18%
  • Veröffentlicht 28.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:21

Incorrect access control in the getAccessDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain access-device policy and client state information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.